Live data from Hacker News

Copy Fail

copy.fail

1–10 of 545 posts

Re: Copy Fail

#4
post #3

What is the rationale behind naming CVEs and individual domains? Marketing?

It makes sure people don't forget about the vulnerabilities, at least

Re: Copy Fail

#6

Is there a readable version of the exploit readily available by any chance? Gotta admit that I failed binary-zip-interpretation-with-naked-eye class twice

The binary "zip" isn't the exploit, it's the shellcode. The exploit is the rest, which changes the code of a SUID executable (su).

Re: Copy Fail

#7
post #3

What is the rationale behind naming CVEs and individual domains? Marketing?

Probably to some extent it is marketing, but generally it has to do with significant bug finds to get the message out to the people who need to apply patches and/or be informed. Heartbleed, Log4Shell, etc.

Very few CVE’s get names dedicated to them like this, because usually when they do - it is very serious, as in this case.

Re: Copy Fail

#9
This looks like an extraordinary find at first glance.

Does this mean you can go from a basic web shell from a shared hosting account to root? I can see how that could wreak havoc really quickly.

Re: Copy Fail

#10
If this is verified, this is a very big deal. Root access on any shared computer. Additionally do we know what kernel versions and stable versions have the patch?
Post reply on HN